Rogue ScreenConnect Clients Used in Worm-Like VBScript Attack
Attackers are leveraging compromised ConnectWise ScreenConnect clients to spread malware automatically to new connections. The campaign uses diverse entry points including tech support scams and phishing.
TL;DR
- Threat actors hijacked ConnectWise ScreenConnect clients to propagate malware.
- A four-stage VBScript chain was delivered to newly connected hosts.
- Initial access vectors included Quick Assist scams, phishing MSI installers, and fake software.
- The attack exhibits worm-like behavior by spreading without user interaction.
- Organizations using ScreenConnect should audit client integrity immediately.
Cybersecurity researchers have uncovered a concerning attack pattern where compromised ConnectWise ScreenConnect clients are being used to spread malware in a self-propagating manner. This worm-like behavior allows attackers to automatically infect newly connected systems without requiring additional user interaction.
The malicious activity leverages a four-stage VBScript payload delivery mechanism. According to Huntress Labs, the attackers gained initial access through various methods including tech support scams using Quick Assist, phishing emails containing malicious MSI installers, and deceptive software downloads.
Attack Vector Diversity
- Three distinct initial access methods were identified across unrelated incidents.
- Quick Assist-based technical support scams served as one entry point.
- Phishing campaigns distributed malicious MSI installer packages.
- Fake software downloads were used to compromise target environments.
- All paths led to compromised ScreenConnect clients serving malicious VBScript.
Propagation Mechanism
- Once inside, the malware establishes persistence within ScreenConnect client installations.
- New connections to the compromised client automatically receive the four-stage VBScript payload.
- The attack spreads laterally without requiring separate exploitation of each target.
- This behavior mimics traditional network worms but operates within remote desktop software.
- No user interaction required on the newly connecting host for infection to occur.
Security Implications
- Organizations using ConnectWise ScreenConnect should verify client integrity immediately.
- Remote desktop and support software now represent high-risk propagation vectors.
- Traditional endpoint protection may not detect this type of client-side compromise.
- Incident response should focus on identifying unauthorized ScreenConnect modifications.
- Supply chain security practices need to account for legitimate software being weaponized.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.